Hawk: Rapid Android Malware Detection Through Heterogeneous Graph Attention Networks

被引:36
|
作者
Hei, Yiming [1 ]
Yang, Renyu [2 ]
Peng, Hao [1 ]
Wang, Lihong [3 ]
Xu, Xiaolin [3 ]
Liu, Jianwei [1 ]
Liu, Hong [4 ,5 ]
Xu, Jie [2 ]
Sun, Lichao [6 ]
机构
[1] Beihang Univ, Sch Cyber Sci & Technol, Beijing 100083, Peoples R China
[2] Univ Leeds, Sch Comp, Leeds LS2 9JT, W Yorkshire, England
[3] Coordinat Ctr China, Natl Comp Network Emergency Response Tech Team, Beijing 100029, Peoples R China
[4] East China Normal Univ, Sch Comp Sci & Software Engn, Shanghai 200241, Peoples R China
[5] Shanghai Trusted Ind Control Platform Co Ltd, Shanghai 200062, Peoples R China
[6] Lehigh Univ, Dept Comp Sci & Engn, Bethlehem, PA 18015 USA
基金
英国工程与自然科学研究理事会;
关键词
Malware; Semantics; Feature extraction; Training; Numerical models; Data models; Predictive models; Android; graph representation learning; heterogeneous information network (HIN); malware detection;
D O I
10.1109/TNNLS.2021.3105617
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Android is undergoing unprecedented malicious threats daily, but the existing methods for malware detection often fail to cope with evolving camouflage in malware. To address this issue, we present Hawk, a new malware detection framework for evolutionary Android applications. We model Android entities and behavioral relationships as a heterogeneous information network (HIN), exploiting its rich semantic meta-structures for specifying implicit higher order relationships. An incremental learning model is created to handle the applications that manifest dynamically, without the need for reconstructing the whole HIN and the subsequent embedding model. The model can pinpoint rapidly the proximity between a new application and existing in-sample applications and aggregate their numerical embeddings under various semantics. Our experiments examine more than 80,860 malicious and 100,375 benign applications developed over a period of seven years, showing that Hawk achieves the highest detection accuracy against baselines and takes only 3.5 ms on average to detect an out-of-sample application, with the accelerated training time of 50x faster than the existing approach.
引用
收藏
页码:4703 / 4717
页数:15
相关论文
共 50 条
  • [41] SFCGDroid: android malware detection based on sensitive function call graph
    Sibo Shi
    Shengwei Tian
    Bo Wang
    Tiejun Zhou
    Guanxin Chen
    [J]. International Journal of Information Security, 2023, 22 : 1115 - 1124
  • [42] Android Malware Detection Based on Structural Features of the Function Call Graph
    Yang, Yang
    Du, Xuehui
    Yang, Zhi
    Liu, Xing
    [J]. ELECTRONICS, 2021, 10 (02) : 1 - 18
  • [43] Automatic Detection of Android Malware via Hybrid Graph Neural Network
    Zhang, Chunyan
    Zhou, Qinglei
    Huang, Yizhao
    Tang, Ke
    Gui, Hairen
    Liu, Fudong
    [J]. WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2022, 2022
  • [44] An Attention-Based Approach to Enhance the Detection and Classification of Android Malware
    Ghourabi, Abdallah
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 80 (02): : 2743 - 2760
  • [45] Detection of Android Malware App through Feature Extraction and Classification of Android Image
    Khan, Mohd Abdul Rahim
    Kumar, Nand
    Tripathi, R. C.
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (05) : 906 - 914
  • [46] Intention-aware Heterogeneous Graph Attention Networks for Fraud Transactions Detection
    Liu, Can
    Sun, Li
    Ao, Xiang
    Feng, Jinghua
    He, Qing
    Yang, Hao
    [J]. KDD '21: PROCEEDINGS OF THE 27TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2021, : 3280 - 3288
  • [47] Android Malware Detection using Sequential Convolutional Neural Networks
    Sun, XingPing
    Peng, JiaYuan
    Kang, HongWei
    Shen, Yong
    [J]. 2018 INTERNATIONAL CONFERENCE ON COMPUTER INFORMATION SCIENCE AND APPLICATION TECHNOLOGY, 2019, 1168
  • [48] Heterogeneous graph attention networks for passage retrieval
    Albarede, Lucas
    Mulhem, Philippe
    Goeuriot, Lorraine
    Marie, Sylvain
    Le Pape-Gardeux, Claude
    Chardin-Segui, Trinidad
    [J]. INFORMATION RETRIEVAL JOURNAL, 2023, 26 (1-2):
  • [49] Heterogeneous graph attention networks for passage retrieval
    Lucas Albarede
    Philippe Mulhem
    Lorraine Goeuriot
    Sylvain Marié
    Claude Le Pape-Gardeux
    Trinidad Chardin-Segui
    [J]. Information Retrieval Journal, 2023, 26
  • [50] Android Malware Detection using Convolutional Deep Neural Networks
    Bourebaa, Fatima
    Benmohammed, Mohamed
    [J]. 2020 4TH INTERNATIONAL CONFERENCE ON ADVANCED ASPECTS OF SOFTWARE ENGINEERING (ICAASE'2020): 4TH INTERNATIONAL CONFERENCE ON ADVANCED ASPECTS OF SOFTWARE ENGINEERING, 2020, : 52 - 58